First published: Wed Oct 15 2008(Updated: )
fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gentoo Cman | =2.02.00-r1 | |
Gentoo Fence | =2.02.00-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4580 has a medium severity rating since it allows local users to modify arbitrary files.
To fix CVE-2008-4580, ensure that proper permissions are set for the fence_manual.fifo temporary file to prevent symlink attacks.
CVE-2008-4580 affects fence 2.02.00-r1 and cman 2.02.00-r1 in Gentoo.
CVE-2008-4580 involves a symlink attack which allows unauthorized file modification.
Local users on systems running the affected versions of fence and cman are impacted by CVE-2008-4580.